alpha-ad6ae7 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited alpha-ad6ae7 (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Codex Plugin Discovery is a Codex skill that helps find task-relevant Codex plugins from two official OpenAI plugin repositories:
openai/pluginsopenai/role-based-pluginsIt is intentionally scoped to metadata generated from those repositories. It does not read local Codex plugin caches, does not inspect the full Codex App Plugin Directory, and does not install plugins automatically.
In Codex, invoke Skill Installer with the GitHub skill path:
@Skill Installer https://github.com/caozhangni/codex-plugin-discovery/tree/main/skills/codex-plugin-discoveryOr run the installer script directly:
python3 ~/.codex/skills/.system/skill-installer/scripts/install-skill-from-github.py \
--url https://github.com/caozhangni/codex-plugin-discovery/tree/main/skills/codex-plugin-discoveryRestart Codex after installing so the skill metadata is picked up.
Ask for plugin recommendations with a task or category:
What Codex plugin could help me make a slide deck?Find a Codex plugin for analyzing spreadsheets.Ask for recently added plugins:
What Codex plugins were added in the past 14 days?Ask what a specific plugin does:
What does the Google Drive plugin do?Broad questions such as "what plugins can I use?" are answered concisely. The skill does not dump the full index.
The generated index is stored at:
skills/codex-plugin-discovery/index/plugins-index.jsonRegenerate it with:
cd skills/codex-plugin-discovery
python3 scripts/build_index.py --cache-dir .cache --output index/plugins-index.json
rm -rf .cacheThe builder reads git history from both source repositories so each direct plugin manifest records when it first appeared in its own repository. That first-seen metadata powers recent-plugin queries.
This repository also includes a plugin package at:
plugins/codex-plugin-discoveryThe plugin bundles the same skill under plugins/codex-plugin-discovery/skills/codex-plugin-discovery.
Run the skill tests:
PYTHONDONTWRITEBYTECODE=1 python3 -m unittest discover -s skills/codex-plugin-discovery/tests -vValidate the skill and plugin manifests:
python3 ~/.codex/skills/.system/skill-creator/scripts/quick_validate.py skills/codex-plugin-discovery
python3 ~/.codex/skills/.system/plugin-creator/scripts/validate_plugin.py plugins/codex-plugin-discoveryMIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.